← Back
CWE-306

2,645 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1F5
21Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 more
Jun 17, 2026
Oct 16, 2024
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not eval...Show more
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
-
-
Jun 17, 2026
Oct 16, 2024
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked...Show more
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.Show less
1Oracle
1Mysql
Jun 17, 2026
Oct 15, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker wi...Show more
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).Show less
1Hp
151jl02b Firmware
F9a29a FirmwareF9a29b Firmware+12 more
Jun 17, 2026
Oct 15, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
2Helmholz
Mbconnectline
2Mbnet.mini Firmware
Rex 100 Firmware
Jun 17, 2026
Oct 15, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
2Helmholz
Mbconnectline
2Mbnet.mini Firmware
Rex 100 Firmware
Jun 17, 2026
Oct 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
1Ragic
1Enterprise Cloud Database
Jun 17, 2026
Oct 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
-
-
Jun 17, 2026
Oct 14, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process
-
-
Jun 17, 2026
Oct 14, 2024
8.8 HIGH· v4
9.4 CRITICAL· v3
N/A· v2
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downlo...Show more
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.Show less
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process
-
-
Jul 5, 2026
Oct 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process
-
-
Jun 17, 2026
Oct 11, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.
1Gitlab
1Gitlab
Jun 17, 2026
Oct 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary bra...Show more
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.Show less
1Lagunaisw
1Wp Users Masquerade
Jun 17, 2026
Oct 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' functi...Show more
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.Show less
1Microsoft
1Visual Studio Code
Jun 17, 2026
Oct 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.